Train Floor

Privacy Policy

Last updated 27 August 2026

This describes the app as it actually works, field by field, not as a template. If something here does not match what TrainFloor does, the policy is wrong and we want to hear about it.

The short version

Who we are

TrainFloor is a product of ManuSoft Inc., 918 E Old Willow Rd, Unit 101, Prospect Heights, Illinois 60070, United States. ManuSoft Inc. decides why and how the data described here is handled, which under the GDPR makes it the controller and under United States state privacy laws the business. Where this policy says we, it means ManuSoft Inc.

Anything about your data goes to [email protected], or to the postal address above.

What TrainFloor collects

Your account

There are two ways in and no others: Continue with Apple, and Continue with Google. There is no sign-up form, nothing to type and no password to set, so there is no password of yours anywhere in TrainFloor. What we receive is the email address the provider hands back, which is what your account is identified by and which Settings shows you. If you use Sign in with Apple and choose to hide your address, TrainFloor receives Apple's private relay address and never sees your real one.

Your profile

A handle and a display name, which are required. Everything else is optional: a biography, a location, years of training experience, gender, an avatar, a cover image, and links to your accounts elsewhere. Location is a free-text field you type, such as a city. TrainFloor never requests or receives GPS or device location, and the app declares no location permission on either platform.

What you post

Workouts and the equipment and body parts tagged on them. Images, YouTube links, and voice notes, which are stored with their length and a waveform of their loudness so the app can draw the bars. Comments, replies, reactions, and direct messages. Highlights, which are the same kinds of attachment posted to expire on their own.

What you train

Two records and no others, and they are worth naming exactly. Starting a workout writes one row holding which workout it was, that it was you, how many seconds you spent on it, and when you started. Posting a result to a leaderboard writes one row holding the time, rounds, reps, weight, the unit you chose, whether it was as prescribed, and when you recorded it.

Nothing else about your body is collected. There are no vital signs, no heart rate, no weight or body measurements of yours, no diagnoses, no symptoms and no medical history, because nothing in the app asks for them.

Who you follow

Accounts you follow, block, mute or save, and threads you have cleared from your own inbox, so the app can show them back to you the way you left them.

Your settings

Notification preferences, and the switches that control whether you appear on leaderboards, whether your reaction counts are hidden, and who may message, comment or post scores.

What you tap on a coach's storefront

A coach may put outbound links on their storefront, and a tap on one is recorded. The record holds which coach it was, that it was you, what kind of link it was, the workout you arrived from if you arrived from one, and the hour it happened. One tap an hour is kept per coach and reader, so this counts visits rather than clicks.

This is stated plainly because it is the only behaviour of yours that TrainFloor records for a commercial reason: a coach is shown how many times their links were reached, and that figure is what the business sells them. The coach is shown a number, never you. Nothing identifies you to them, no profile of you is built from it, none of it goes to an advertiser, and the same figure is counted whichever link was tapped.

Asking a coach to train you

If you ask a coach to train you live, we store what you wrote: your goal, when you would like to train, whether it is at their gym, yours or elsewhere, which of their gyms if you picked one, which coach you asked, and whether the request is new, opened or declined.

The coach is not shown who you are until they open the request, and a coach pays to open one after their first three. When they open it they see your name and can message you. Deleting your account removes the request.

If you coach: your gyms and your schedule

A coach may add the gyms they work out of - a label they type, and the coordinates of the place they picked - and dated blocks of open availability or named sessions. Those coordinates are a place a coach chose to publish, never a reading from their phone. Both are shown to anybody looking at that coach's page, which is the point of them.

Payments, if you are a coach

Reading, training and posting are free, and none of this applies to you until you buy one of the two things a coach can buy: an introduction to somebody who has asked to train with you, or a further promo on your storefront. The card is typed into Stripe and never into TrainFloor. The sheet that appears in the app and the page that opens in your browser are both Stripe's, and no card number, expiry or security code ever reaches us.

What we keep is the record of the charge: which of the two you bought, what it was against, the amount, the currency, Stripe's identifier for the payment, whether it succeeded, and when it settled, was refunded or was disputed. Your profile also carries the customer identifier Stripe issues you, which is how a second purchase can use the card you already saved with them. Stripe is sent that profile identifier and the email address on your account, so that a charge can be traced back to you when you write to us about one.

Stripe's own software is built into the app to draw that sheet. It starts only when you open it, and Stripe collects device signals of its own for fraud detection when a card is submitted. Those signals are Stripe's, not ours, and Stripe states they are used for fraud detection and security and never for advertising.

Your device, only for notifications

If you turn on push notifications, TrainFloor stores a push token and your platform, iOS or Android, so a notification can reach the right device. Turning notifications off removes it.

Safety

Reports you file about other people or their content, including what you reported, the reason, any detail you wrote, and how it was resolved. These are kept after resolution so a pattern of behaviour can be recognised.

What your phone sends to somebody else without passing through us

Two things in the app are fetched by your own device from a company that is not us, and neither reaches our servers at any point. They are listed here because we never see it is not the same as nobody does.

What TrainFloor does not collect

The app asks for two device permissions and no others: the microphone, when you record a voice note, and notifications, if you turn them on. Both are refusable and the app works without either.

Why we hold each of these

WhatWhyLegal basis under GDPR
The email address Apple or Google returnsTo create your account and let you sign back inPerformance of a contract
Profile and postsTo show them to other people, which is what the app is forPerformance of a contract
Training records and resultsTo draw your history and leaderboardsPerformance of a contract
A tap on a coach's linkTo tell a coach how often their links were reached, which is what they are paying us forLegitimate interests, being the operation of the marketplace itself
A request to train with a coachTo carry your request to them and let them answer itPerformance of a contract
Push tokenTo deliver a notification you asked forConsent, withdrawn by turning notifications off
Automated review of posted textTo keep the app free of abuse and illegal contentLegitimate interests, and our obligations to app stores
ReportsTo act on abuse and recognise repeat behaviourLegitimate interests
Payment records, and your Stripe customer identifierTo charge you for what you bought, to prove afterwards what you were charged, to answer a dispute, and to keep our booksPerformance of a contract, and a legal obligation to keep records of what we are paid

Where we rely on legitimate interests you may object, and how to do that is under Your rights.

Automated review of what you post

When you post a workout, its text is sent to a language model operated by Moonshot AI PTE. LTD. so it can be classified and checked for spam, abuse and unsafe content. Comments, and private messages that somebody has reported, may be reviewed the same way. This means text you post leaves our systems and is processed on servers in Singapore, which is outside the EU and the United Kingdom. Nothing that names you goes with it: no profile identifier, no handle and no workout identifier is ever in the payload, so what Moonshot receives is the words alone.

We ask Moonshot to use that text for the decision and nothing else, and we should be straight about the limit of that. Moonshot's published terms reserve the right to use content submitted to their API to provide, maintain, develop, support and improve their services, and they offer a restriction on that only by separate written agreement. We have asked for one and do not have it yet. Until we do, our instruction is what governs between us and them, and their terms are what they have reserved for themselves. If that is not acceptable to you, do not post text you would not want read by a third party, and see Who else processes your data for what we are doing about it.

This is an automated decision that can cause a post to be held or rejected. It does not have a legal or similarly significant effect on you, and a person reviews anything you dispute. Write to us and we will look at it.

Who else processes your data

WhoWhat they handleWhereTheir role
SupabaseSign-in, the database, and stored images and voice notesUnited StatesOur processor
HetznerThe server that receives a posted workout and runs the reviewGermanyOur processor
Moonshot AIAutomated review of posted textSingaporeOur processor by our instruction; see above
StripeCard payments from coaches, and the card details we never seeUnited StatesOur processor, and a controller in its own right
AppleSign in with Apple, and the device token and text of every push to an iPhoneUnited StatesA controller in its own right
GoogleSign in with Google, Play distribution, and YouTube thumbnails and embeds fetched by your deviceUnited StatesA controller in its own right
CloudflareThis website, the domain, and email to our published addressesUnited StatesOur processor
OpenStreetMap FoundationA gym search typed by a coach, sent by their own deviceUnited Kingdom and NetherlandsA third party your device contacts

Three of these do not act only on our instructions, and saying otherwise would be untrue. Stripe is our processor for taking the payment and a controller in its own right for fraud prevention and financial regulation, because the card networks oblige it to decide those for itself. Apple and Google are controllers in their own right for sign-in and for store distribution: neither offers us a processing agreement for those services, and what they do with an Apple ID or a Google account is governed by their own policies rather than by this one. The OpenStreetMap Foundation has no relationship with us at all; a gym search reaches it the same way tapping a coach's Instagram link reaches Instagram.

Your data is not sold, not rented, and not shared with advertisers or data brokers. We disclose data to law enforcement only where we are legally required to, or where somebody is in immediate danger.

Where your data goes

TrainFloor is operated from the United States and its database is hosted there, so if you use the app from the European Economic Area or the United Kingdom your data is transferred out of them. What covers each transfer differs, and the honest answer is not the same sentence for every party.

What other people can see

Your handle, name, biography, location, experience, gender if you set it, avatar, cover image, and links are visible to anybody signed in to TrainFloor, and so is a posted workout unless you set that workout to followers only. Comments and reactions are public on the thing they belong to. Leaderboard placements are public unless you turn them off. A coach's gyms and schedule are public on their page. Direct messages are visible only to you and the person you sent them to.

There is no private-account switch. The audience is set per workout rather than per person: each one you post is either visible to everybody signed in or to your followers only, and that is enforced by the database rather than by the app. Blocking somebody stops them contacting you and hides their content from you.

How long it is kept

WhatHow long
Your account and everything attached to itUntil you delete it
Direct messagesUntil either side's account is deleted
Taps on a coach's linksDeleted with either account, yours or the coach's
Payment records, if you are a coachSeven years from the charge, even if you delete your account
Reports you filedKept after resolution, so repeat behaviour is visible
Database backupsA copy is taken daily. The two most recent stay on our own server and older copies are held off-site for about a month, then deleted

Payment records are the one thing that outlives your account. We have to keep them: tax law requires it, and a card payment can be disputed months after it was made. Deleting your account unlinks your name from the charge rather than deleting the charge, so what is left is the amount, the date, what it bought and Stripe's own reference for it. Stripe keeps its copy either way. This is the exception in Article 17(3) of the GDPR for data we are required by law to keep, or need in order to defend a legal claim.

Deleting your account

You can delete your account from inside the app, in Settings. It removes your sign-in record, your profile and the content attached to it. Your payment records stay, with your name unlinked from them, for the reason given above. Deletion is immediate and cannot be undone. Copies already written to a backup disappear when that backup is overwritten.

If you would rather we did it, or you want a copy of your data first, write to [email protected].

Your rights

You can see and change your profile in the app at any time, and delete your account. Depending on where you live you also have the right to:

To exercise any of these, write to [email protected]. We answer within 30 days, or 45 days where a United States state law allows it, and we will tell you if we need longer. We will not treat you differently for asking - no feature is withdrawn, no price changes, and nothing about your account is degraded.

If we refuse a request, you may appeal it by replying to our answer and saying so. An appeal is looked at by somebody who did not decide it the first time, and we answer within 45 days with our reasons. If we refuse again, the laws of Virginia, Colorado, Connecticut, Texas, Oregon, Montana and several other states let you complain to your state Attorney General, and we will give you the link.

If you are in California: we do not sell or share personal information as the CCPA defines those terms, and we have not done so in the preceding twelve months, so there is no Do Not Sell or Share link to offer you. We do not knowingly sell the personal information of anybody under 16. The categories we collect, why, and who receives them are set out in full above rather than summarised, which is the same disclosure the CCPA asks for.

If you are in any other United States state with a privacy law - Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and the rest as they take effect - the rights above are yours on the same terms, and you may use an authorised agent. We do not sell personal data, we do not use it for targeted advertising, and we do not profile anybody in a way that produces legal or similarly significant effects, so there is nothing for an opt-out to switch off. We honour Global Privacy Control and any other universal opt-out signal your browser sends, and there is nothing on this website for it to stop.

Cookies

The app uses no cookies. This website sets none, and carries no analytics and no trackers.

Children

TrainFloor is not for children under 13, and we do not knowingly collect anything from them. Where local law sets a higher age for consent to data processing, that age applies instead. If you believe a child has an account, write to us and it will be removed.

Security

Data is encrypted in transit. Access to the database is restricted per account by row-level security, so one account cannot read another's private data. The credential that can bypass those rules is held only on our server and never ships inside the app. No system is perfectly secure; if a breach occurs that puts your data at risk we will tell you and the relevant authority.

Changes

If this policy changes materially, the date at the top changes and the app will point you here. Continuing to use TrainFloor after a change means the new version applies.

Contact

ManuSoft Inc.
918 E Old Willow Rd, Unit 101
Prospect Heights, Illinois 60070
United States

Privacy: [email protected]
Everything else: [email protected]